Microsoft Releases October 2022 Security Updates
Scheduled updates for Microsoft products
Summary
Scheduled updates for Microsoft products
Affected platforms
The following platforms are known to be affected:
The following platforms are also known to be affected:
- Active Directory Domain Services
- Azure
- Azure Arc
- Client Server Run-time Subsystem (CSRSS)
- Microsoft Graphics Component
- Microsoft WDAC OLE DB provider for SQL
- NuGet Client
- Remote Access Service Point-to-Point Tunneling Protocol
- Role: Windows Hyper-V
- Service Fabric
- Visual Studio Code
- Windows Active Directory Certificate Services
- Windows ALPC
- Windows CD-ROM Driver
- Windows COM+ Event System Service
- Windows Connected User Experiences and Telemetry
- Windows CryptoAPI
- Windows DHCP Client
- Windows Distributed File System (DFS)
- Windows DWM Core Library
- Windows Event Logging Service
- Windows Group Policy
- Windows Group Policy Preference Client
- Windows Internet Key Exchange (IKE) Protocol
- Windows Kernel
- Windows Local Security Authority (LSA)
- Windows Local Security Authority Subsystem Service (LSASS)
- Windows Local Session Manager (LSM)
- Windows NTFS
- Windows NTLM
- Windows ODBC Driver
- Windows Perception Simulation Service
- Windows Point-to-Point Tunneling Protocol
- Windows Portable Device Enumerator Service
- Windows Print Spooler Components
- Windows Resilient File System (ReFS)
- Windows Secure Channel
- Windows Security Support Provider Interface
- Windows Server Remotely Accessible Registry Keys
- Windows Server Service
- Windows Storage
- Windows TCP/IP
- Windows USB Serial Driver
- Windows Web Account Manager
- Windows Win32K
- Windows WLAN Service
- Windows Workstation Service
Threat details
Introduction
Microsoft has released updates to address 84 vulnerabilities in Microsoft products, with 15 of them rated as critical. An unauthenticated, remote attacker could exploit some of these vulnerabilities to take control of an affected system.
Exploitation in the wild
Microsoft have reported exploitation of the Windows COM+ Event System Service Elevation of Privilege vulnerability, known as CVE-2022-41033, and CISA has added it to their Known Exploited Vulnerabilities Catalog.
A proof-of-concept has been released for a critical Windows CryptoAPI spoofing bug known as CVE-2022-34689. The vulnerability was originally discovered by the US National Security Agency (NSA) and National Cyber Security Centre (NCSC). Affected organisations are encouraged to read Microsoft's guidance for these vulnerabilities and apply any relevant updates.
Threat updates
| Date | Update |
|---|---|
| 26 Jan 2023 |
Proof-of-concept released for a critical Windows CryptoAPI spoofing bug
This article has been updated to reflect the status of exploitation of CVE-2022-34689. |
| 21 Oct 2022 |
Microsoft issues Out-of-Band (OOB) advisory for SSL/TLS handshake fail
Microsoft has reported that after installing KB5018421, some types of SSL (Secure Sockets Layer) and TLS (Transport Layer Security) connections might have handshake failures. Affected organisation should review Window Release Health message for their relevant system:
|
Remediation advice
Affected organisations are encouraged to review Microsoft’s October 2022 Security Update Summary and Deployment Information and apply the relevant updates.
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 26 January 2023 2:32 pm